Description
Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device.
Problem types
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
Credits
Chokri Hammedi
References
www.exploit-db.com/exploits/51036
www.exploit-db.com/exploits/51036 (ExploitDB-51036)
www.skyjos.com/ (Vendor Homepage)
apps.apple.com/us/app/owlfiles-file-manager/id510282524 (Official App Store Listing)
www.vulncheck.com/...es/owlfiles-file-manager-path-traversal (VulnCheck Advisory: Owlfiles File Manager 12.0.1 - Path Traversal)